Beacon makes it easy to store and work with all the contacts that make your organisation possible. Under data protection laws (such as the UK GDPR), individuals have the right to ask for a copy of the personal data you hold on them—commonly known as a Subject Access Request (SAR) or Special Access Request.
This article looks at best practices for how to find, gather, and securely share a person's information.
Note: The steps below are recommendations designed to make this process easy for charities. Because charities can handle and store lots of additional and complex data, each organisation's legal and compliance obligations may vary. Always refer to your own data protection policies!
Reasons for a Subject Access Request (SAR)
The most common reasons someone will submit a SAR are:
They want to understand what information your charity holds about them.
They want to verify that you are processing their data lawfully.
They are preparing to exercise other rights, such as the right to erasure (right to be forgotten) or the right to update their information.
Individuals can request this data verbally or in writing, and they don't even have to specifically use the phrase "Subject Access Request."
Gathering records to share
When a request comes in, you need to identify the personal data you hold on that individual across your database. Because charities can handle lots of additional data beyond a simple name and address, you'll need to look at the whole picture.
Whilst we can't tell you exactly which fields your charity might consider personal data, we do have some tips and considerations for you!
Check the main Person record
The primary place to look is the individual's Person record. This contains their core contact details, demographics, and consent preferences. You can easily export this record directly from Beacon using the export tool.
Note: Don't forget deleted records! If someone was previously removed using Beacon's standard delete function, they may be soft-deleted/archived rather than permanently deleted (like on your computer). Because soft-deleted records (and their related data) still exist in your Beacon database, they legally remain within the scope of a Subject Access Request. Be sure to check your deleted records views so no active or soft-deleted personal data is missed. More information here.
Consider all the different ways that someone interacts with your charity
You may have many different touchpoints that contain personal information. For example: A payment, an event attendance, a case or beneficiary record, a membership, or emails and notes logged on their timeline.
Tip: Go to the person's record and review all of their 'Related' records. Ensure you are capturing the data in these related records, as they often contain personally identifiable information (PII) like dietary requirements, specific case details, or personal conversations. However, you likely won't be showing all Related records on the Person record (as these cards are customisable). You may want to go through each record type in Beacon and perform a search for the person's name and email.
Before sharing any data, spot-check your export
Make sure to review the information you have gathered. Ensure you are only providing the personal data of the person requesting it.
Important: Account for historical PII logged in the Timeline. The timeline on a record logs historical updates over time—which often includes previous PII (such as former home addresses, phone numbers, or updated names). If a SAR requires you to share historical logs or audit trails, keep in mind that timeline entries cannot be easily exported using standard export tools. You may need to manually review the record's timeline and copy/paste these historical entries into your export file.
If an email or note on their timeline mentions another person (like a family member or another supporter), you must redact or remove the other person's information to protect their privacy before sharing the data.
Sharing the data securely
There are two main approaches to providing this data to your supporters:
Recommended approach: Secure exports and encrypted sharing
Alternative option: Let supporters manage data via the Beacon Portal
Providing this information in a clear, easy-to-read format is important, but making sure it doesn't fall into the wrong hands is critical!
Recommended approach: Secure exports and encrypted sharing
Our recommendation for when you need to fulfil a comprehensive Subject Access Request is to export the relevant records and share them via a secure, password-protected method.
1. Exporting the data (Tip: Use the List View) While you can set up a dedicated export template using Beacon's Export Tool, for a single person's SAR, it is usually much easier to export directly from the List View.
Filter the Person list view to show only the individual.
Customise your visible columns/fields to ensure all fields are selected so no hidden data is left out.
Click Export to CSV.
Repeat this process from the list view of any related records (such as Payments, Memberships, or Activities) filtered for that person.
2. Securing the file
Never send a raw, unencrypted CSV containing personal data as a standard email attachment. Standard email is not always secure. Instead, you should:
Put the exported files into a ZIP folder and protect it with a strong password.
Or, upload the files to a secure cloud storage service (like Google Drive, SharePoint, or Dropbox) and generate a restricted, expiring link.
3. Sharing the password separately
If you are using a password-protected file, always communicate the password via a different method than the file itself. For example: Email the encrypted ZIP file to the supporter, but send the password to open it via an SMS text message or a phone call.
Alternative option: Let supporters manage data via the Beacon Portal
Occasionally, a supporter doesn't actually need a complete legal export of everything you hold on them; they simply want to know what basic details and communication preferences you have on file so they can update them.
In this scenario, you can give them access to the Beacon Portal.
While the Portal might not cover a full legal Subject Access Request if they want absolutely everything (like internal staff notes or historical case files), it empowers supporters to log in securely, view, and manage their primary data themselves. This often satisfies their curiosity in a highly secure, automated way without your team needing to run a manual export!
Frequently asked questions
Does the GDPR or UK GDPR specify a timeframe for responding to a SAR?
Yes. Typically, under UK GDPR, you must respond to a Subject Access Request without delay and at the latest within one month of receipt.
Do we have to share absolutely everything?
Generally, yes—you must share the personal data you hold about them. However, you must be careful not to share personal data belonging to someone else. You may need to redact internal notes or emails if they compromise another person's privacy.
How each organisation handles redaction and complex data is highly personal, and we recommend speaking to a data security or privacy expert for advice.
Can we charge a fee for providing this data?
In most cases, no. You must provide a copy of the information free of charge. You can only charge a reasonable fee if the request is "manifestly unfounded or excessive."
